PluginProbe
Kit (formerly ConvertKit) – Email Newsletter, Email Marketing, Membership, Subscribers and Landing Pages / 3.4.6
Kit (formerly ConvertKit) – Email Newsletter, Email Marketing, Membership, Subscribers and Landing Pages v3.4.6
3.4.6 3.4.5 3.4.4 3.4.3 3.4.2 3.4.1 3.4.0 3.3.9 3.3.8 3.3.7 3.3.6 3.3.5 3.3.4 3.3.3 3.3.2 3.3.1 2.2.0 2.2.1 2.2.2 2.2.3 2.2.4 2.2.5 2.2.6 2.2.7 2.2.8 All 199 releases
← All changes | admin/importers/class-convertkit-admin-importer.php +26 -4 3.4.2 → 3.4.6 View file →
@@ -261,8 +261,11 @@
261 261
262 262 // Replace the third party Form Shortcode with the Kit Form Shortcode.
263 263 $post_content = $this->replace_shortcodes_in_content( $post_content, $third_party_form_id, $form_id );
264 264
265 + // Double escape backslashes so that wp_update_post doesn't remove them.
266 + $post_content = str_replace( '\\', '\\\\', $post_content );
267 +
265 268 // Update the Post content.
266 269 wp_update_post(
267 270 array(
268 271 'ID' => $post_id,
@@ -292,8 +295,9 @@
292 295 // If there's no shortcode ID attribute, match shortcodes with or without any attribute.
293 296 if ( ! $this->shortcode_id_attribute ) {
294 297 $pattern = '/\[' // Start regex with an opening square bracket.
295 298 . preg_quote( $this->shortcode_name, '/' ) // Match the shortcode name, escaping any regex special chars.
299 + . '(?=[\s\]\/])' // Ensure the shortcode name is complete, so e.g. [name_other] isn't matched.
296 300 . '[^\]]*?\]/i'; // Match any other characters (non-greedy) up to the closing square bracket, case-insensitive.
297 301
298 302 return preg_replace(
299 303 $pattern,
@@ -309,12 +313,13 @@
309 313 // Run a replacement pass per attribute name.
310 314 foreach ( $id_attributes as $id_attribute ) {
311 315 $pattern = '/\[' // Start regex with an opening square bracket.
312 316 . preg_quote( $this->shortcode_name, '/' ) // Match the shortcode name, escaping any regex special chars.
317 + . '(?=[\s\]\/])' // Ensure the shortcode name is complete, so e.g. [name_other] isn't matched.
313 318 . '[^\]]*?' // Match any characters that are not a closing square bracket, non-greedy.
314 - . '\b' . preg_quote( $id_attribute, '/' ) // Match the id attribute word boundary and escape as needed.
319 + . '\s' . preg_quote( $id_attribute, '/' ) // Match the id attribute, preceded by whitespace so e.g. data-id isn't matched.
315 320 . '\s*=\s*' // Match optional whitespace around an equals sign.
316 - . '(?:"' . preg_quote( (string) $third_party_form_id, '/' ) . '"|\'' . preg_quote( (string) $third_party_form_id, '/' ) . '\'|' . preg_quote( (string) $third_party_form_id, '/' ) . ')' // Match the form ID, double quotes, single quotes or unquoted.
321 + . '(?:"' . preg_quote( (string) $third_party_form_id, '/' ) . '"|\'' . preg_quote( (string) $third_party_form_id, '/' ) . '\'|' . preg_quote( (string) $third_party_form_id, '/' ) . '(?=[\s\]\/]))' // Match the exact form ID, double quotes, single quotes or unquoted.
317 322 . '[^\]]*?\]/i'; // Match any other characters (non-greedy) up to the closing square bracket, case-insensitive.
318 323
319 324 $content = preg_replace(
320 325 $pattern,
@@ -378,8 +383,9 @@
378 383 // If there's no shortcode ID attribute, match shortcodes with or without any attribute and treat any match as a single "form".
379 384 if ( ! $this->shortcode_id_attribute ) {
380 385 $pattern = '/\[' // Start regex with an opening square bracket.
381 386 . preg_quote( $this->shortcode_name, '/' ) // Match the shortcode name, escaping any regex special chars.
387 + . '(?=[\s\]\/])' // Ensure the shortcode name is complete, so e.g. [name_other] isn't matched.
382 388 . '(?:\s+[^\]]*)?' // Optionally match any attributes (key/value pairs), non-greedy.
383 389 . '[^\]]*?\]/i'; // Match up to closing bracket, case-insensitive.
384 390
385 391 preg_match_all( $pattern, $content, $matches );
@@ -400,8 +406,9 @@
400 406 $form_ids = array();
401 407 foreach ( $id_attributes as $id_attribute ) {
402 408 $pattern = '/\[' // Start regex with an opening square bracket.
403 409 . preg_quote( $this->shortcode_name, '/' ) // Match the shortcode name, escaping any regex special chars.
410 + . '(?=[\s\]\/])' // Ensure the shortcode name is complete, so e.g. [name_other] isn't matched.
404 411 . '(?:\s+[^\]]*)?' // Optionally match any attributes (key/value pairs), non-greedy.
405 412 . preg_quote( $id_attribute, '/' ) // Match the id attribute name.
406 413 . '\s*=\s*' // Optional whitespace, equals sign, optional whitespace.
407 414 . '(?:"([^"]+)"|\'([^\']+)\'|([^\s\]]+))' // Capture double quoted, single quoted or unquoted value.
@@ -537,9 +544,9 @@
537 544 continue;
538 545 }
539 546
540 547 // Skip if not a third party form block.
541 - if ( strpos( $block['blockName'], $this->block_name ) === false ) {
548 + if ( $block['blockName'] !== $this->block_name ) {
542 549 continue;
543 550 }
544 551
545 552 // If the block ID attribute is not set, the third party Plugin doesn't use IDs,
@@ -555,9 +562,9 @@
555 562 if ( ! array_key_exists( $id_attribute, $block['attrs'] ) ) {
556 563 continue;
557 564 }
558 565
559 - if ( stripos( $block['attrs'][ $id_attribute ], (string) $third_party_form_id ) === false ) {
566 + if ( ! $this->block_id_attribute_matches( $block['attrs'][ $id_attribute ], $third_party_form_id ) ) {
560 567 continue;
561 568 }
562 569
563 570 $matched = true;
@@ -582,8 +589,23 @@
582 589 );
583 590 }
584 591
585 592 return $blocks;
593 +
594 + }
595 +
596 + /**
597 + * Returns whether the given block ID attribute value matches the third party form ID.
598 + *
599 + * @since 3.4.5
600 + *
601 + * @param mixed $value Block ID attribute value.
602 + * @param string|int $third_party_form_id Third Party Form ID.
603 + * @return bool
604 + */
605 + protected function block_id_attribute_matches( $value, $third_party_form_id ) {
606 +
607 + return (string) $value === (string) $third_party_form_id;
586 608
587 609 }
588 610
589 611 }